Since version 3.2.2, an error message
Unable to query the configuration of the service - Acces Denied (0x5)
is issued when you try to query the status of a windows service created with JSW.
Looking at the code, it appears that you have changed to access rights you use when creating/managing the service.
In particular you no longer use SERVICE_ALL_ACCES when managing the service.
Is it the intented behaviour? or is it a regression.
How can we have the wrapper working like in 3.2.1 ?
Up through 3.3.1 The SERVICE_ALL_ACCESS privilege was being requested for any service related operation. The SERVICE_ALL_ACCESS is actually made up of a number of more specific privileges. By requesting them all when only the SERVICE_QUERY_STATUS privilege was required we were actually requiring more privilege than necessary. It was reported by a user that users who were able to start and stop other services were not able to do so.
From 3.3.2 release notes: "Fix a problem on Windows where the ability to start and stop the Wrapper as a service using the Wrapper itself was requiring the Administrator permission when a lower permission should have been possible. The Wrapper should now allow service control to do whatever is possible from the Services control panel. "
This should have been a loosening of restrictions but I obviously did not change things correctly.
There are a number of ways to query the status of the wrapper's service. Could you let me know exactly how you are doing so along with the queried operation? What is the account that is performing the operation? What account is the Wrapper service running as?
Thanks.
Leif
Hi Leif,
We query the status of the service using the -q command line option of the wrapper.exe.
This command is issued under a user account with no particular privileges.
The service is running under the LocalSystem account.
It was working like a charm in 3.3.1
Thanks
Olivier
As you said, this was a problem introduced in version 3.3.2.
When you run "wrapper -q wrapper.conf" you will see something like the
following in the console:
---
wrapper | The Test Wrapper Sample Application Service is installed.
wrapper | Unable to query the configuration of the Test Wrapper
Sample Application service - アクセスが拒否されました。 (0x5)
wrapper | Running: Yes
---
The test for whether or not the service is running is working
correctly. The Access error is in requesting the additional service
configuration information but it does not affect the results about the
service status.
With the fix in place, the output looks like this:
---
wrapper | The Test Wrapper Sample Application Service is installed.
wrapper | Start Type: Automatic
wrapper | Interactive: Yes
wrapper | Running: Yes
---
This fix will be included in the release of version 3.3.4
Cheers,
Leif
"Up through 3.3.1 The SERVICE_ALL_ACCESS privilege was being requested for any service related operation. The SERVICE_ALL_ACCESS is actually made up of a number of more specific privileges. By requesting them all when only the SERVICE_QUERY_STATUS privilege was required we were actually requiring more privilege than necessary."
Is that actually the case? If I look at the wrapperServiceStatus() function in wrapper_win.c, I see a call to not only QueryServiceStatus(), but also QueryServiceConfig(). Since the error message is complaining about being unable to query the *configuration* of the service, maybe the fix here is simply changing the last argument on the call to OpenService() from 'SERVICE_QUERY_STATUS' (without the single quotes) to 'SERVICE_QUERY_CONFIG | SERVICE_QUERY_STATUS' (again, without the single quotes).
Sorry, please ignore my previous comment... Just noticed that this was fixed. Thanks!